Vulnerabilities
Vulnerable Software
Security Vulnerabilities
libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.
CVSS Score
7.5
EPSS Score
0.004
Published
2026-09-11
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
CVSS Score
7.1
EPSS Score
0.003
Published
2026-09-11
strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
CVSS Score
5.9
EPSS Score
0.004
Published
2026-09-11
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
CVSS Score
3.7
EPSS Score
0.002
Published
2026-09-11
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
CVSS Score
5.9
EPSS Score
0.004
Published
2026-09-11
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
CVSS Score
9.6
EPSS Score
0.004
Published
2026-09-10
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
CVSS Score
9.6
EPSS Score
0.003
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
CVSS Score
8.8
EPSS Score
0.005
Published
2026-09-10
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-09-10
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-09-10


Contact Us

Shodan ® - All rights reserved